Executive assessment
Today's brief leads with Ghostscript: Heap-based Buffer Overflow. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 05 leads today because it is the only listed issue with exploitation in the wild, and model-specific fixed firmware is listed. The Ghostscript issue Finding 01 is the closest rival because it is CRITICAL with PoC exploitation, but the listing does not report in-the-wild exploitation. Patch order: Finding 05 (It has exploitation in the wild, and fixed firmware is listed for affected Zyxel GS1900 models); Finding 01 (It is the only CRITICAL finding and has PoC exploitation; the listed control says not to rely on -dSAFER); Finding 10 (PoC exploitation exists for an authorization bypass, and Argo Workflows 4.1.4 is listed as fixed).
Also today: 5 more n8n CVEs (CVE-2026-85169, CVE-2026-72767, CVE-2026-72772, CVE-2026-72769, CVE-2026-72762) in the same disclosure wave as the n8n cards of 2026-09-11 and 2026-09-20; none reported exploited; carried as a note rather than a finding.
Also today: 4 more Concrete CMS CVEs (CVE-2026-18110, CVE-2026-18423, CVE-2026-18424, CVE-2026-85387) in the same disclosure wave as the Concrete CMS card of 2026-09-21; none reported exploited; carried as a note rather than a finding.
Finding 01 — Ghostscript: Heap-based Buffer Overflow
What changed: It was discovered that Ghostscript incorrectly handled JPEG 2000 image components with mismatched subsampling factors. An attacker could possibly use this issue to cause Ghostscript to crash or execute arbitrary code if it opened a specially crafted file.
Technical evidence: CVE-2026-39919; CVSS v4.0 9.3; weakness CWE-122; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: For web servers, disable automated PDF preview generation until patched; do not rely on -dSAFER as a mitigation. ([securityonline.info](https://securityonline.info/ghostscript-buffer-overflow-cve-2026-39919/), [bugs.ghostscript.com](https://bugs.ghostscript.com/show_bug.cgi?id=709666), [vulncheck.com](https://www.vulncheck.com/advisories/ghostscript-heap-buffer-overflow-via-jpeg-2000-output-adapter), +2 more)
Action: Map CVE-2026-39919 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8791-1)
Finding 02 — BioStar BIOS Update Utility: Write-what-where Condition
What changed: A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler.
Technical evidence: CVE-2026-94146; CVSS v4.0 9.3; weakness CWE-123, CWE-119; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-94146 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-94146)
Finding 03 — ColorFul iGameCenter: Untrusted Pointer Dereference
What changed: A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler.
Technical evidence: CVE-2026-94403; CVSS v4.0 9.3; weakness CWE-822; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-94403 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-94403)
Finding 04 — Moore Threads MTT S80 Driver Package: Heap-based Buffer Overflow
What changed: A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler.
Technical evidence: CVE-2026-94424; CVSS v4.0 9.3; weakness CWE-122, CWE-119; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-94424 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-94424)
Finding 05 — Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
What changed: CISA added the Zyxel GS1900 Series stack-based buffer overflow to its Known Exploited Vulnerabilities catalog, establishing active exploitation. Operators should treat affected switches as an immediate remediation and threat-hunting priority.
Technical evidence: CVE-2026-7273; CVSS v3.1 8.8; weakness CWE-121; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Disable HTTP/HTTPS web management where console or out-of-band administration is available. Otherwise isolate management interfaces from user VLANs and use strict ACLs to block untrusted HTTP sessions. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-7273/), [greynoise.io](https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation), [community.zyxel.com](https://community.zyxel.com/en/discussion/33340/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches))
Affected: GS1900-8: 2.90(AAHH.1)C0 and earlier; GS1900-8HP: 2.90(AAHI.1)C0 and earlier; GS1900-10HP: 2.90(AAZI.1)C0 and earlier; GS1900-16: 2.90(AAHJ.1)C0 and earlier; GS1900-24: 2.90(AAHL.1)C0 and earlier. ([community.zyxel.com](https://community.zyxel.com/en/discussion/33340/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches))
Fix: GS1900-8: 2.90(AAHH.2)C0; GS1900-8HP: 2.90(AAHI.2)C0; GS1900-10HP: 2.90(AAZI.2)C0; GS1900-16: 2.90(AAHJ.2)C0; GS1900-24: 2.90(AAHL.2)C0; GS1900-24E: 2.90(AAHK.2)C0; GS1900-24EP: 2.90(ABTO.2)C0. ([community.zyxel.com](https://community.zyxel.com/en/discussion/33340/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches))
Panel assessment: Patch now: CISA KEV-confirmed exploitation makes this an immediate priority, and a reachable switch management interface can turn one vulnerable GS1900 device into a control-plane risk for the network segments depending on it. (priority: patch now)
Action: Map CVE-2026-7273 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-7273)
Finding 06 — Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
What changed: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
Technical evidence: CVE-2026-88097; CVSS v3.1 8.1; weakness CWE-416; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Microsoft reports that the vulnerability was not exploited at the time of original publication. ([msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-88097), [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-88097))
Affected: Microsoft Edge (Chromium-based) versions from 1.0.0.0 to before 153.0.4234.46. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-88097))
Fix: Microsoft Edge (Chromium-based) build 153.0.4234.46. ([msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-88097))
Action: Map CVE-2026-88097 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-88097)
Finding 07 — IBM MQ: Integer Overflow or Wraparound
What changed: NVD records CVE-2026-11725 (IBM MQ): Integer Overflow or Wraparound, CVSS v3.1 8.8; affected: IBM MQ Server 9.1.0.0-9.1.0.37 LTS, 9.2.0.0-9.2.0.43 LTS, 9.3.0.0-9.3.0.41 LTS, 9.3.0.0-9.3.5.1 CD, 9.4.0.0-9.4.0.25 LTS, 9.4.0.0-9.4.5.1 CD, and 10.0.0.0.
Technical evidence: CVE-2026-11725; CVSS v3.1 8.8; weakness CWE-190; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: IBM states that no workarounds or mitigations are available. ([ibm.com](https://www.ibm.com/support/pages/node/7284944), [ibm.com](https://www.ibm.com/support/pages/node/7284711))
Affected: IBM MQ Server 9.1.0.0-9.1.0.37 LTS, 9.2.0.0-9.2.0.43 LTS, 9.3.0.0-9.3.0.41 LTS, 9.3.0.0-9.3.5.1 CD, 9.4.0.0-9.4.0.25 LTS, 9.4.0.0-9.4.5.1 CD, and 10.0.0.0. ([ibm.com](https://www.ibm.com/support/pages/node/7284944), [ibm.com](https://www.ibm.com/support/pages/node/7284711))
Fix: IBM MQ: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, or 10.0.0.5 for 9.3 CD, 9.4 CD and 10.0.0.0. IBM MQ Appliance: 9.4.0.26 or later (9.4 LTS), 10.0.0.5 or later (9.4 CD M2003 and 10 LTS). ([ibm.com](https://www.ibm.com/support/pages/node/7284944), [ibm.com](https://www.ibm.com/support/pages/node/7284711))
Action: Map CVE-2026-11725 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-11725)
Finding 08 — Multiple vulnerabilities in Oracle Hyperion Financial Management
What changed: CVE coverage: CVE-2026-87196, CVE-2026-87197, CVE-2026-87200, CVE-2026-87205. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.
Technical evidence: CVE-2026-87196; CVSS v3.1 8.2; weakness CWE-306; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: If patching is delayed, block HTTP and HTTPS access to Oracle Hyperion Financial Management where operationally feasible. Test the restriction on non-production systems because Oracle warns it may break application functionality. ([oracle.com](https://www.oracle.com/security-alerts/cspusep2026.html))
Panel assessment: Patch now, especially before any wider exposure review is allowed to drift, because these are unauthenticated HTTP(S)-reachable flaws with a potential blast radius of critical or all Oracle Hyperion Financial Management-accessible data, even though exploitation is not confirmed. The likely attack path is a direct web request to a critical function missing authentication, reaching Hyperion financial-management data without first needing valid credentials. (priority: patch now)
Action: Map CVE-2026-87196 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-87196)
Finding 09 — Multiple vulnerabilities in IBM Guardium Data Protection
What changed: IBM Guardium Data Protection 12.2 carries 4 CVEs across 2 advisories: OS Command Injection; SQL injection vulnerability in the Load Balancer Groups component. CVE coverage: CVE-2026-81626, CVE-2026-81669, CVE-2026-81933, CVE-2026-81937.
Technical evidence: CVE-2026-81626; CVSS v3.1 8.6; weakness CWE-89; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Fix: SqlGuard_12.0p233_FixPack; Apply fix pack SqlGuard_12.0p233_FixPack to IBM Guardium Data Protection 12.2 ([ibm.com](https://www.ibm.com/support/pages/node/7288040))
Action: Map CVE-2026-81626 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-81626)
Finding 10 — Argo Workflows: Authorization Bypass Through User-Controlled Key
What changed: Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.
Technical evidence: CVE-2026-93991; CVSS v4.0 8.3; weakness CWE-639; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Disable the workflow archive or restrict who can reach Argo Server until patching is possible. ([github.com](https://github.com/argoproj/argo-workflows/security/advisories/GHSA-q65w-j2vp-47c4))
Affected: Argo Workflows 4.1.0 through 4.1.3; the 4.0 and 3.x lines are not affected. ([github.com](https://github.com/argoproj/argo-workflows/security/advisories/GHSA-q65w-j2vp-47c4))
Fix: Argo Workflows 4.1.4. ([github.com](https://github.com/argoproj/argo-workflows/security/advisories/GHSA-q65w-j2vp-47c4))
Action: Map CVE-2026-93991 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93991)
Finding 11 — Jenkins Script Security Plugin: Unsafe Reflection
What changed: NVD records CVE-2026-92126 (Jenkins Script Security Plugin): Unsafe Reflection, CVSS v3.1 8.5; affected: Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier.
Technical evidence: CVE-2026-92126; CVSS v3.1 8.5; weakness CWE-470; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: If patching is delayed, revoke script definition and Pipeline configuration permissions from non-administrative users. Require manual script approval for all sandboxed scripts and reject any script that uses @Builder with builderStrategy. ([jenkins.io](https://www.jenkins.io/security/advisory/2026-09-16/#SECURITY-3925%20(2)), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-92126/))
Affected: Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier. ([jenkins.io](https://www.jenkins.io/security/advisory/2026-09-16/#SECURITY-3925%20(2)))
Fix: Jenkins Script Security Plugin 1422.v06869826dd9b_. ([jenkins.io](https://www.jenkins.io/security/advisory/2026-09-16/#SECURITY-3925%20(2)))
Action: Map CVE-2026-92126 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-92126)
Finding 12 — Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500: NULL Pointer Dereference
What changed: An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.
Technical evidence: CVE-2025-62817; CVSS v3.1 7.5; weakness CWE-476; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: SentinelOne advises preferring Wi-Fi with cellular disabled in high-risk environments until firmware updates are deployed, and monitoring MDM telemetry for modem crashes and baseband panic reports. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2025-62817/))
Action: Map CVE-2025-62817 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-62817)
Finding 13 — Multiple vulnerabilities in nginx ignition
What changed: nginx ignition carries 3 CVEs across 3 advisories: Race Condition; Allocation of Resources Without Limits or Throttling; Improper Authentication. CVE coverage: CVE-2026-61628, CVE-2026-61629, CVE-2026-61630.
Technical evidence: CVE-2026-61628; CVSS v3.1 8.1; weakness CWE-362; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict nginx-ignition management access to trusted administrative networks while onboarding is incomplete or reset, and block external POST requests to /api/users/onboarding/finish. ([github.com](https://github.com/advisories/GHSA-pxcx-fv34-x9p5), [github.com](https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.41.1), [github.com](https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-jr34-h97m-9hpx), +2 more)
Affected: Versions earlier than 0.0.0-20260621194639-0586b4e55ab; Versions 2.29.0 through 2.40.0 ([github.com](https://github.com/advisories/GHSA-pxcx-fv34-x9p5), [github.com](https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-jr34-h97m-9hpx), [github.com](https://github.com/advisories/GHSA-hf33-q6cf-c66f))
Fix: Version 2.40.1; 0.0.0-20260328015550-8d35e1eb5dd6 ([github.com](https://github.com/advisories/GHSA-pxcx-fv34-x9p5), [github.com](https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.41.1), [github.com](https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-jr34-h97m-9hpx), +1 more)
Action: Map CVE-2026-61628 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-pxcx-fv34-x9p5)
Finding 14 — Multiple vulnerabilities in Dell Update Package Framework
What changed: CVE coverage: CVE-2026-71179, CVE-2026-71180, CVE-2026-86358. The cited advisories disclose: Improper Neutralization of Special Elements used in an OS Command.
Technical evidence: CVE-2026-71179; CVSS v3.1 7.3; weakness CWE-78; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict local access and enforce least privilege on affected hosts. BlackTree reports no confirmed exploitation evidence for all three CVEs. ([dell.com](https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities), [cve.blacktree.nl](https://cve.blacktree.nl/cve/CVE-2026-71179), [cve.blacktree.nl](https://cve.blacktree.nl/cve/CVE-2026-71180), +1 more)
Affected: Dell Update Package (DUP) Framework versions prior to 26.07.03. ([dell.com](https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities))
Fix: Dell Update Package (DUP) Framework version 26.07.03 or later. ([dell.com](https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities))
Action: Map CVE-2026-71179 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-71179)
Finding 15 — WordPress Click2Shell flaw lets hackers execute PHP on the server
What changed: A disclosed WordPress Core cross-site request forgery technique dubbed Click2Shell can induce an administrator to trigger server-side PHP execution, and technical details plus proof-of-concept code are public. The current evidence is a single editorial report and does not establish exploitation in the wild.
Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
fixed version or patch state unknown
[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/)